Skip to content

完成 M3/M4 操作边界与 provider secret execution - #12

Merged
specter119 merged 2 commits into
masterfrom
feat/m4-provider-secret-operations
Sep 18, 2026
Merged

specter119 merged 2 commits into
masterfrom
feat/m4-provider-secret-operations

Conversation

@lodyai

@lodyai lodyai Bot commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

摘要

  • 在冻结的 v3/v4/v5 契约内完成 M3 边界修复与执行闭合。
  • 完成独立 v6 provider/secret execution:显式 subprocess 授权、受限 rbw、秘密渲染隔离、owner-only target、独立 metadata-only journal、诊断 cache 与平台 fail-closed。
  • 补充维护文档、M4 关闭记录、消融实验、secret sentinel 与 Linux/Python 3.12–3.14 CI 配置。

验证

  • 343 项 unittest 通过。
  • M3 四项消融、M4 消融与 secret sentinel 通过。
  • Ruff、ty、compileall、uv lock、git diff check 与隔离 prek 全部通过。
  • wheel 在 Python 3.12/3.13/3.14 通过;sdist 在 Python 3.12/3.14 通过。

范围说明

自动 replay/rollback、network provider 与抵御非合作 writer 的强一致性仍不在本 PR 范围内。

Create the independent baseline before removing the staged inode and keep
old target descriptors open while constructing external replacements.
Assert distinct file identities without depending on filesystem allocation.

Preserve the existing indeterminate, recovery, and cleanup assertions.
@specter119
specter119 merged commit 2552ef8 into master Sep 18, 2026
8 checks passed
@specter119
specter119 deleted the feat/m4-provider-secret-operations branch September 18, 2026 23:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant